 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Recommendations for OU and group policy design</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/recommendations-for-ou-and-group-policy-design/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/recommendations-for-ou-and-group-policy-design/</link>
	<description></description>
	<lastBuildDate>Sat, 25 May 2013 16:32:12 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: humblenetadmin</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/recommendations-for-ou-and-group-policy-design/#comment-49164</link>
		<dc:creator>humblenetadmin</dc:creator>
		<pubDate>Wed, 28 Jun 2006 09:28:03 +0000</pubDate>
		<guid isPermaLink="false">#comment-49164</guid>
		<description><![CDATA[GregNottage

rayne427?s post is right on. That is how I manage the AD structure as well. In my last position as Net Admin. I broke down the AD OU Structure into departmental levels. The primary reason for doing this was for granularity in applying Group Policies for our employees. And the other was because we started providing terminal service access to run applications to our clients. I needed to be able to maintain control of each TS client?s access and desktop, and that control would need to be different at three different levels for each client, as well as different for each client. Following is a diagram of sorts of how I did it. Hope this helps and good luck

AD Domain (Default Domain GPO)
&#124;
-Sales OU (Sale OU GPO)
&#124;
-Customer Service OU (CustServ OU GPO
&#124;
-IS OU (IS OU GPO)
&#124;
-Terminal Service Users OU (TS OU GPO)
   &#124;
------Client A (Client A OU GPO)
       &#124;
---------Branch (ClnABrn OU GPO)
       &#124;
---------Administration (ClnAAdmin OU GPO)
       &#124;
---------Corporate (ClnACorp OU GPO)
   &#124;
------Client B (Client B OU GPO)
       &#124;
---------Branch (ClnBBrn OU GPO)
       &#124;
---------Administration (ClnAAdmin OU GPO)
       &#124;
---------Corporate (ClnACorp OU GPO)
]]></description>
		<content:encoded><![CDATA[<p>GregNottage</p>
<p>rayne427?s post is right on. That is how I manage the AD structure as well. In my last position as Net Admin. I broke down the AD OU Structure into departmental levels. The primary reason for doing this was for granularity in applying Group Policies for our employees. And the other was because we started providing terminal service access to run applications to our clients. I needed to be able to maintain control of each TS client?s access and desktop, and that control would need to be different at three different levels for each client, as well as different for each client. Following is a diagram of sorts of how I did it. Hope this helps and good luck</p>
<p>AD Domain (Default Domain GPO)<br />
|<br />
-Sales OU (Sale OU GPO)<br />
|<br />
-Customer Service OU (CustServ OU GPO<br />
|<br />
-IS OU (IS OU GPO)<br />
|<br />
-Terminal Service Users OU (TS OU GPO)<br />
   |<br />
&#8212;&#8212;Client A (Client A OU GPO)<br />
       |<br />
&#8212;&#8212;&#8212;Branch (ClnABrn OU GPO)<br />
       |<br />
&#8212;&#8212;&#8212;Administration (ClnAAdmin OU GPO)<br />
       |<br />
&#8212;&#8212;&#8212;Corporate (ClnACorp OU GPO)<br />
   |<br />
&#8212;&#8212;Client B (Client B OU GPO)<br />
       |<br />
&#8212;&#8212;&#8212;Branch (ClnBBrn OU GPO)<br />
       |<br />
&#8212;&#8212;&#8212;Administration (ClnAAdmin OU GPO)<br />
       |<br />
&#8212;&#8212;&#8212;Corporate (ClnACorp OU GPO)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 6/9 queries in 0.015 seconds using memcached
Object Caching 268/271 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-25 17:25:34 -->